Patents by Inventor Marcus Wong

Marcus Wong has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20170264439
    Abstract: Embodiment mutual authentication and security agreement (MASA) protocols may use independently generated integrity and/or encryption keys to securely communicate private information exchanged between UEs and various network-side devices (e.g., base stations, MMEs, HSSs, etc.). In particular, embodiment MASA protocols may use an initial authentication request (IAR) encryption key (KIARENC) to encrypt UE specific information (e.g., an IMSI, etc.) in an IAR message and/or an initial authentication response (IAS) encryption key (KIASENC) to encrypt private information in an IAS message. Additionally, embodiment MASA protocols may use an IAR integrity protection key (KIARINT) to verify the integrity of information in an IAR message and/or an IAS integrity protection key (KIASINT) to verify the integrity of information in an IAS message. The KIARENC, KIARINT, KIASENC, and/or KIASINT may be independently computed by the UE and a home subscriber server (HSS).
    Type: Application
    Filed: March 8, 2017
    Publication date: September 14, 2017
    Inventors: Ahmad Shawky Muhanna, Marcus Wong
  • Publication number: 20170126682
    Abstract: The disclosure relates to technology for provisioning out-of-network user equipment with a network relay in a communications network. The network relay device receives an authentication key request message from user equipment including a user equipment identity and an authentication server identity, and communicates the authentication key request message to an authentication server having the authentication server identity. The network relay device communicates a relay authentication key response received from the authentication server to the user equipment such that a secure communication is established between the user equipment and the network. A relay authentication key is generated during establishment of the secure communication between the user equipment and authentication server, and a session with the user equipment is authenticated using a session key generated by the user equipment based on the relay authentication key.
    Type: Application
    Filed: October 30, 2015
    Publication date: May 4, 2017
    Inventors: Marcus Wong, Zhibi Wang
  • Patent number: 9585012
    Abstract: A method for establishing a secure connection between a station and an access point includes transmitting a communications system management message to the station, the communications system management message including an access point nonce. The method also includes receiving a station nonce from the station, and determining a first security key according to the access point nonce and the station nonce. The method further includes securing a connection between the station and the access point using the first security key.
    Type: Grant
    Filed: May 14, 2012
    Date of Patent: February 28, 2017
    Assignee: Futurewei Technologies, Inc.
    Inventor: Marcus Wong
  • Patent number: 9357386
    Abstract: Embodiments are provided for enabling identity verification of messages originating from a radio station, such as a Femto cell, to a gateway, such as a Femto gateway. In an embodiment, a radio station establishes a first connection for authentication with a security gateway, sends authentication information on the first connection, and receives in return an Internet Protocol (IP) address assigned to the radio station. The security gateway updates a Domain Name System (DNS) to map between the IP address and a DNS name for the radio station. The radio station also establishes a second connection for control messages with a second gateway, and sends the IP address and an identity of the radio station on the second connection. The mapping between the IP address and the DNS name enables the second gateway to identify messages on the second connection between the radio station and the second gateway.
    Type: Grant
    Filed: June 20, 2013
    Date of Patent: May 31, 2016
    Assignee: Futurewei Technologies, Inc.
    Inventors: Peter J. McCann, Marcus Wong
  • Patent number: 8769341
    Abstract: A system and method for recovering from a failure is disclosed. A preferred embodiment comprises downloading a first patch into a base station, installing the first patch, loading the first patch, and validating the first patch. Once the first patch has been validated, a second patch may be downloaded, installed, loaded, and verified. This incremental remediation approach allows for the conservation of resources if the system is non-recoverable, as this will become evident prior to a complete download and install is performed.
    Type: Grant
    Filed: August 24, 2011
    Date of Patent: July 1, 2014
    Assignee: FutureWei Technologies, Inc.
    Inventor: Marcus Wong
  • Patent number: 8654716
    Abstract: A system and method for name binding for multiple packet data network access is provided. A method for communications device operation includes attaching to a first packet data network through an access network, thereby creating an access point name, triggering a connection to a second packet data network through the access network, and receiving an acknowledgement to the trigger. The triggering occurs over the access point name, and the acknowledgement comprises an address for the communications device. The address is allocated by a gateway for the second packet data network, and the address is allocated based on a binding generated from an identifier of the communications device, an identifier of the access point name, and a parameter.
    Type: Grant
    Filed: November 13, 2009
    Date of Patent: February 18, 2014
    Assignee: FutureWei Technologies, Inc.
    Inventor: Marcus Wong
  • Publication number: 20140004830
    Abstract: Embodiments are provided for enabling identity verification of messages originating from a radio station, such as a Femto cell, to a gateway, such as a Femto gateway. In an embodiment, a radio station establishes a first connection for authentication with a security gateway, sends authentication information on the first connection, and receives in return an Internet Protocol (IP) address assigned to the radio station. The security gateway updates a Domain Name System (DNS) to map between the IP address and a DNS name for the radio station. The radio station also establishes a second connection for control messages with a second gateway, and sends the IP address and an identity of the radio station on the second connection. The mapping between the IP address and the DNS name enables the second gateway to identify messages on the second connection between the radio station and the second gateway.
    Type: Application
    Filed: June 20, 2013
    Publication date: January 2, 2014
    Inventors: Peter J. McCann, Marcus Wong
  • Publication number: 20130301833
    Abstract: A method for establishing a secure connection between a station and an access point includes transmitting a communications system management message to the station, the communications system management message including an access point nonce. The method also includes receiving a station nonce from the station, and determining a first security key according to the access point nonce and the station nonce. The method further includes securing a connection between the station and the access point using the first security key.
    Type: Application
    Filed: May 14, 2012
    Publication date: November 14, 2013
    Applicant: FutureWei Technologies, Inc.
    Inventor: Marcus Wong
  • Publication number: 20120054535
    Abstract: A system and method for recovering from a failure is disclosed. A preferred embodiment comprises downloading a first patch into a base station, installing the first patch, loading the first patch, and validating the first patch. Once the first patch has been validated, a second patch may be downloaded, installed, loaded, and verified. This incremental remediation approach allows for the conservation of resources if the system is non-recoverable, as this will become evident prior to a complete download and install is performed.
    Type: Application
    Filed: August 24, 2011
    Publication date: March 1, 2012
    Applicant: FutureWei Technologies, Inc.
    Inventor: Marcus Wong
  • Patent number: 8000478
    Abstract: A key handshake method in a wireless local area network (LAN) capable of performing authentication between two wirelessly connected stations by exchanging keys once is provided. Because the security key for authentication can be exchanged by one 4-way handshake between an authenticator and a supplicant in a wireless LAN, an authentication delay can be prevented.
    Type: Grant
    Filed: May 23, 2006
    Date of Patent: August 16, 2011
    Assignee: Samsung Electronics Co., Ltd.
    Inventors: Marcus Wong, Sergey Bezzateev
  • Publication number: 20100124198
    Abstract: A system and method for name binding for multiple packet data network access is provided. A method for communications device operation includes attaching to a first packet data network through an access network, thereby creating an access point name, triggering a connection to a second packet data network through the access network, and receiving an acknowledgement to the trigger. The triggering occurs over the access point name, and the acknowledgement comprises an address for the communications device. The address is allocated by a gateway for the second packet data network, and the address is allocated based on a binding generated from an identifier of the communications device, an identifier of the access point name, and a parameter.
    Type: Application
    Filed: November 13, 2009
    Publication date: May 20, 2010
    Applicant: FutureWei Technologies, Inc.
    Inventor: Marcus Wong
  • Patent number: 7551848
    Abstract: A photographic light system, imaging device and method for providing different types of photographic light uses a single multifunctional light module to produce the different types of photographic light. The multifunctional light module includes a number of semiconductor light source devices, such as light emitting diodes (LED), which are controlled by a light module controller. The multifunctional light module can be used to produce an autofocus auxiliary light, a red-eye reducing light and a flash of light.
    Type: Grant
    Filed: May 10, 2005
    Date of Patent: June 23, 2009
    Assignee: Avago Technologies ECBU IP (Singapore) Pte. Ltd.
    Inventors: Kian Shin Lee, Janet Bee Yin Chua, Chi Yuen Marcus Wong
  • Publication number: 20070192600
    Abstract: A key handshake method in a wireless local area network (LAN) capable of performing authentication between two wirelessly connected stations by exchanging keys once is provided. Because the security key for authentication can be exchanged by one 4-way handshake between an authenticator and a supplicant in a wireless LAN, an authentication delay can be prevented.
    Type: Application
    Filed: May 23, 2006
    Publication date: August 16, 2007
    Inventors: Marcus Wong, Sergey Bezzateev
  • Publication number: 20050193197
    Abstract: In the method, a value of a first cryptosync for a communication session is derived based on a value of a second cryptosync. The second cryptosync has a longer life than the first cryptosync.
    Type: Application
    Filed: February 26, 2004
    Publication date: September 1, 2005
    Inventors: Sarvar Patel, Marcus Wong
  • Publication number: 20020146127
    Abstract: A system and method uses a common key provided to a first wireless unit and a second wireless unit to use in secure communications between the first and second wireless units over at least one wireless communications system. By providing a common key to the first and second wireless units, the common key security system alleviates the at least one wireless communications system from having to perform the security methods used to provide secure communications between the first and second wireless units. For example, the encryption/decryption of the communications between the first wireless unit and the second wireless unit can be performed at the first and second wireless units using the common key. In certain embodiments, the first and second wireless units and the serving wireless communications system(s) still perform authentication and obtain keys CK1 and CK2 as described above.
    Type: Application
    Filed: April 5, 2001
    Publication date: October 10, 2002
    Inventor: Marcus Wong
  • Patent number: 6094487
    Abstract: An encryption key generation system generates encryption keys at both an originating terminal and a terminating terminal of a wireless network. A central controller generates a shared secret based on the identification information of a requesting terminal and a first number, which may be random. The central controller broadcasts the first number to all terminals. A second number is generated by the central controller incorporating the shared secret data and the terminating terminal's identification information. The requesting terminal generates the shared secret data using the first number and predetermined algorithms and generates an encryption key based on the first number and the shared secret data. The terminating terminal decodes the shared secret data from the second number, and generates the same encryption key using the first number and the shared secret data.
    Type: Grant
    Filed: March 4, 1998
    Date of Patent: July 25, 2000
    Assignee: AT&T Corporation
    Inventors: Theodore Butler, Marcus Wong